Agent skill

Polygraph

by BankrBot in BankrBot/skills

Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

No licenceAuto-check passedAgent Workflows

Install Polygraph

skills CLI
$ npx skills add BankrBot/skills --skill polygraph -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BankrBot/skills polygraph --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/polygraph .claude/skills/polygraph && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
polygraph
GitHub stars
1.2k
Token cost
~3.4k tokens
SKILL.md length
1,531 words
Files
7 (incl. references)
Skills in repo
104
Repo updated
First seen
Licence
None found

At a glance

Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

  • Works in 3 steps: Grade meets your bar. Default… → Fingerprint still matches. An… → Attestation is trustworthy enough for…
  • An agent needs to check whether an MCP server is safe before using it
  • SKILL.md covers What a grade measures, Check a grade, Verify before you trust (Bankr… and ★ Get your project graded, plus 5 more sections
  • Calls npx and npm

What it does

Polygraph is an agent skill from BankrBot/skills. Behavioral trust grades (A–F) for MCP servers. Use when an agent needs to check whether an MCP server is safe before using it, verify an onchain attestation before trusting or paying a server, look up a server's published grade, get a project graded, or understand why a server received a grade. Polygraph connects to an MCP server the way an agent would, fingerprints its exact tool surface, and runs behavioral probes — prompt-injection (C-01), permission/egress overreach (C-02), sensitive-data leak (C-03), and…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `catalog.json`, `references/bankr-integration.md` and `references/ci-gate.md`).

It sits in Agent Workflows, covering Prompt injection and agent security, MCP servers and CI/CD. It works with Model Context Protocol. The repository describes itself as: Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

When your agent uses it

  • An agent needs to check whether an MCP server is safe before using it
  • Verify an onchain attestation before trusting
  • Paying a server
  • Look up a servers published grade

Example prompts

  • “/polygraph”

Requirements

  • Node.js
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Grade meets your bar. Default (DEFAULT_PASSING): accept A/B, refuse D/F. **For a signed
  2. Fingerprint still matches. An attestation is only valid for the exact tool surface it
  3. Attestation is trustworthy enough for the action. readAttestation binds to our EAS schema

What it can do on your machine

Read from SKILL.md and the folder at commit dc47eed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • polygraph.so
    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Polygraph loads about 3.4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 245 tokens; SKILL.md has 1,531 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~245
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,531 words (~3,371 tokens).

“Agents wire up third-party MCP servers and then trust whatever those servers' tools return. Polygraph tests an MCP server's behavior before your agent does, and assigns a letter grade A–F backed by reproducible evidence.”

— opening of SKILL.md by BankrBot
name
polygraph
emoji
🧪
tags
security, mcp, trust, grade, attestation, base, prompt-injection, agent-safety
visibility
public

Read the full SKILL.md on GitHub

Files

SKILL.md and 6 other files (references) in polygraph of BankrBot/skills.

  • SKILL.md
  • catalog.json
  • logo.svg
  • references/bankr-integration.md
  • references/ci-gate.md
  • references/cli.md
  • references/methodology.md

Open the folder on GitHubat commit dc47eed

Compare with similar skills

Polygraph next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Polygraph compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Polygraph this skillBankrBot/skills1.2k—~3.4kAutomated safety check: PassNone
Claude Docs Consultantcentminmod/my-claude-code-setup2.7k—~959Automated safety check: PassMIT
Automated Triagesickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: PassApache-2.0
Skill Security Auditsickn33/agentic-awesome-skills47k1 repos~1.4kAutomated safety check: PassCC0-1.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Reins Runtime Securitypegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0

Similar skills

  • Claude Docs Consultant

    centminmod/my-claude-code-setup

    Consult official Claude Code documentation from code.claude.com using selective fetching.

    2.7k GitHub stars~959 tokensUpdated 10 days ago
    Agent WorkflowsAuto-check passed
  • Automated Triage

    sickn33/agentic-awesome-skills

    Triage Monte Carlo alerts interactively or build an automated workflow.

    47k GitHub starsUsed in 1 repo~3.2k tokens
    Agent WorkflowsAuto-check passed
  • Skill Security Audit

    sickn33/agentic-awesome-skills

    Audit an Agent Skill, MCP server, connector, or desktop extension before installation by tracing code, dependencies, permissions, credentials, data flow, and irreversible actions.

    47k GitHub starsUsed in 1 repo~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Reins Runtime Security

    pegasi-ai/reins

    Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

    392 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes

More from BankrBot/skills

All 104 skills in this repo
  • OnchainKit App Builder

    BankrBot/skills

    Builds onchain apps with Coinbase's OnchainKit React components and TypeScript utilities: wallet connection, identity, token swaps, transactions and checkout flows.

    1.2k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Lists AgenticBets prediction markets on Base, shows odds, places UP or DOWN bets on token prices in USDC and claims winnings through the Bankr wallet API.

    1.2k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • AI2Human Task Router

    BankrBot/skills

    Creates AI2Human tasks for steps that need a real person, such as manual QA or local checks, and returns a task URL the agent can track.

    1.2k GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • Lets an agent inspect and operate AZZLE V2 tasks on Base through Bankr, from posting and claiming to funding, delivery, release and disputes, behind verified deployment pins.

    1.2k GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • B20 Console

    BankrBot/skills

    Inspect B20 token contract addresses on Base through B20 Console.

    1.2k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Endaoment

    BankrBot/skills

    Donate to charities onchain via Endaoment. An agent skill from BankrBot/skills.

    1.2k GitHub stars~610 tokensUpdated 2 days ago
    Auto-check passed

Questions about Polygraph

What does Polygraph do?

Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills. Polygraph is an agent skill from BankrBot/skills. Behavioral trust grades (A–F) for MCP servers.

When should I use Polygraph?

Polygraph fits situations like: an agent needs to check whether an MCP server is safe before using it; verify an onchain attestation before trusting; paying a server; look up a servers published grade.

How do I install Polygraph in Claude Code?

Run `npx skills add BankrBot/skills --skill polygraph -a claude-code`. Or copy the skill folder (polygraph in BankrBot/skills) into .claude/skills/polygraph in your project. Claude Code loads it when a task matches its description.

How do I install Polygraph in Codex?

Run `npx skills add BankrBot/skills --skill polygraph -a codex`. Or copy the skill folder (polygraph in BankrBot/skills) into .agents/skills/polygraph in your project. Codex loads it when a task matches its description.

Can I use Polygraph in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BankrBot/skills --skill polygraph -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/polygraph, .gemini/skills/polygraph, .github/skills/polygraph and .opencode/skills/polygraph in your project.

What does Polygraph need to run?

Going by SKILL.md and its folder, Polygraph needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js; Docker.

Does Polygraph access the network?

SKILL.md names 2 domains. As links in the text: polygraph.so and npmjs.com. This is read from the text; nothing was executed.

Is Polygraph safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Polygraph use?

No licence was found for Polygraph or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Polygraph use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.2k tokens, read only when the agent opens those files.

What are the alternatives to Polygraph?

Skills that share tags, products or a category with Polygraph: Claude Docs Consultant (centminmod/my-claude-code-setup, 2.7k stars), Automated Triage (sickn33/agentic-awesome-skills, 47k stars), Skill Security Audit (sickn33/agentic-awesome-skills, 47k stars) and Forensify (alexgreensh/repo-forensics, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Polygraph?

BankrBot (a GitHub organization) maintains it in BankrBot/skills, which has 1,201 GitHub stars. The repository holds 104 skills in this directory. The repository was last updated on October 5, 2026.

Source: BankrBot/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.